What Pegasus actually does to a phone — and what reduces your exposure
If you follow the news, you have seen the word Pegasus attached to a story about a hacked journalist, a surveilled lawyer, or a politician reading their own private messages in a leak. It sounds like a plot device. It is not. Pegasus and the tools like it are commercial products — bought by governments, aimed at specific people — and the people on the receiving end almost never realise it is happening.
This is a detailed, plain-language explanation of what this kind of spyware actually does once it reaches a phone: how it gets in, what it can see, why it is so hard to notice, and — the part that matters most — what genuinely reduces your exposure. No hype, no fear-selling; just an honest picture of a real threat and a realistic response to it.
Mercenary spyware, and the industry behind it
“Mercenary” or “commercial” spyware is surveillance software built by private companies and sold, almost always to state agencies, to break into the phones of named individuals. The best known is Pegasus, made by Israel’s NSO Group. But it is far from alone. Predator, from the Intellexa alliance, and Graphite, from Paragon, do broadly the same job for other buyers. This is a mature industry with competing vendors, product tiers, and support contracts.
Two things set these tools apart from ordinary malware. First, the target: they are pointed at specific people — a particular journalist, a named lawyer — not scattered across millions of phones for profit. Second, the capability: they are engineered to defeat a fully patched, mainstream device, which is why they command prices in the hundreds of thousands to millions of dollars per deployment.
And the threat is current, not historical. In July 2026, Amnesty International’s Security Lab published a detailed teardown of how NSO’s system has evolved and industrialised over the years. In 2025, Citizen Lab confirmed the first forensic evidence of Paragon’s Graphite being used in zero-click attacks on journalists in Europe. This is a live, present-day capability that keeps being renewed as defences improve.
How it gets in: “zero-click,” explained
The single most important and most unsettling detail is that the dangerous versions of this spyware need no action from you at all. There is no suspicious link you have to tap, no dodgy attachment you have to open. This is what “zero-click” means: a specially crafted message — often arriving silently through iMessage, WhatsApp, or a similar app — can compromise the device on its own, sometimes without ever showing a visible message.
The way it works is through an exploit chain: a sequence of separate software flaws strung together. One bug gets the attacker’s code running inside a messaging or image-processing component; another escapes the sandbox that is supposed to contain that component; another gains the elevated privileges needed to take over the system. Each link is a distinct, usually unknown (“zero-day”) vulnerability.
The public cases make the pattern concrete. Apple’s 2021 FORCEDENTRY case was a zero-click iMessage exploit that abused the way the phone parsed a disguised image file. In 2023, BLASTPASS was another zero-click iMessage chain, caught by Citizen Lab. In June 2025, a fresh iOS flaw (tracked as CVE-2025-43200) was used to deliver Graphite the same silent way. The pattern repeats on a loop: a new silent delivery method is found, used quietly against a handful of high-value targets, eventually discovered by researchers — and by the time it is patched, the vendors are already working on the next one.
What it can see once it is inside
Once mercenary spyware is running on a phone, the honest assumption is that everything on that phone is exposed. In practical terms it can typically:
- Read your messages — including in end-to-end encrypted apps like Signal and WhatsApp. This is the point people most often misunderstand: encryption protects a message in transit, but the spyware simply reads it on your screen, after your own phone has already decrypted it for you to see. The strongest encryption in the world does not help when the attacker is standing behind your eyes.
- Pull your photos, contacts, calendar, emails, browsing history, and saved passwords.
- Track your location in real time, and reconstruct where you have been.
- Silently switch on the microphone and camera to record your surroundings and conversations, turning the phone into a live bug in your pocket.
- Harvest credentials and tokens that let the operator reach into your cloud accounts, extending the compromise beyond the device itself.
It achieves this because it runs with the highest level of privilege on the device — beneath your apps, beneath your lock screen, beneath your privacy settings. That is exactly why the ordinary protections you rely on, encryption included, do not stop it. The compromise happens underneath all of them.
Why targets almost never notice
The entire business model depends on staying invisible, so these tools are engineered to leave as little trace as possible. Some versions deliberately do not survive a restart — they live only in the phone’s memory and vanish on reboot, specifically so there is nothing left on disk for a forensic investigator to find later. There is usually no battery drain you would notice, no strange icon, no pop-up, no obvious slowdown.
So how do people find out? Almost never from the phone “feeling off.” They find out when an independent research lab like Citizen Lab or Amnesty’s Security Lab examines the device and finds the fingerprints, or when a platform like Apple sends a threat notification to someone it believes was targeted. By definition, if the spyware were easy to notice, it would not be worth what states pay for it.
This leads to an uncomfortable truth that most “signs your phone is hacked” checklists get wrong: for this class of threat, the absence of symptoms is not proof that you are clean. “It seems fine” is precisely the impression a well-built implant is designed to create.
Who is actually targeted
Mercenary spyware is expensive and finite, so it is aimed with intent. The documented targets, again and again, are journalists and their sources, human-rights lawyers and activists, political opposition figures and their staff, diplomats and senior officials, and executives holding sensitive commercial or strategic information. If your work means that what you know, who you talk to, or where you go is valuable to a government or a well-funded adversary, you are in the category these tools are built for. Most people are not — and that honesty matters, because it lets the people who are at risk take it seriously without everyone else panicking.
What actually reduces your exposure
Here is the part that cuts both ways, and it is important to be straight about it. No step available to an individual can guarantee stopping a well-funded government armed with an unknown zero-click exploit. Anyone who promises you a magic shield is selling a fantasy. But exposure is not all-or-nothing, and several measures measurably lower your risk and raise the cost and effort required to target you:
- Keep your operating system updated, promptly. These attacks depend on specific flaws. When Apple or Google patches one, that exact door closes. Updating the same day a security update lands is the single highest-value habit you have.
- Turn on Lockdown Mode (iOS) or its hardened equivalent. It deliberately strips away many of the features — certain message attachment types, some web technologies, wired connections — that these exploit chains abuse. Apple has stated it has disrupted real mercenary-spyware attacks, and researchers have observed it blocking attempts in the wild.
- Reboot regularly — daily if you are high-risk. Because a number of infections live only in memory, a simple restart can clear a non-persistent foothold and forces an attacker to spend another expensive exploit to get back in. Amnesty’s researchers have highlighted routine reboots as a genuine, if partial, mitigation.
- Shrink your attack surface. Fewer messaging apps, caution with unknown attachments and links, and disabling features and services you do not use all reduce the number of ways in.
- Take threat notifications seriously, and get real forensic help. If Apple or Google warns you, or you have specific reason to believe you are a target, do not shrug it off. Tools like Amnesty’s Mobile Verification Toolkit (MVT) and services from digital-rights organisations can examine a device far more rigorously than any on-phone setting, and groups like Access Now’s Digital Security Helpline offer free, confidential support to civil-society targets.
The realistic goal is not to become un-hackable. It is to be a harder, more expensive, more detectable target — because attention, cost, and the risk of exposure are the real constraints on how these tools get used.
Where SireShield fits
You cannot stop the rain. But you can carry an umbrella — and you can know the moment it starts.
For a genuinely high-risk person, the realistic defence is not an impenetrable wall; it is continuous detection, reduced exposure, and fast, informed response. That is what SireShield is built around. Rather than leaving you to guess from battery life or hope a one-time scan catches something designed to hide, it watches your device continuously for the quiet signals mercenary spyware leaves behind, helps you cut down the exposure that makes you an easier target in the first place, and gives you a clear, fast response the moment something changes — instead of finding out months later from someone else’s report.
That is deliberately bounded, honest protection, for the people who are actually in the crosshairs: journalists, lawyers, officials, executives, and anyone entrusted with information worth stealing.
If that describes you or someone you work with, learn more and apply for access.
Further reading: The Citizen Lab’s Pegasus research and Amnesty International’s Security Lab publish ongoing, independent, technical documentation of these tools and how to defend against them.